
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
gatsby-source-comment-server
Advanced tools
A minimal plugin that pulls comments from https://gatsbyjs-comment-server.herokuapp.com/.
The server is a nodeJS server that serves comments and allows posting of new comments from any website.
A blog has been created to test this plugin.
See it here.Note: To load new comments, the server has to be restarted (A fix would come for this in the future).
npm install gatsby-source-comment-server
// or
yarn add gatsby-source-comment-server
Add into your gatsby-config.js
:
//...
module.exports{
plugins: [
{
resolve: "gatsby-source-comment-server",
options: {
website: "Unique URL of a blog/website"
}
}
]
}
It pulls comments from the server using the website as a distinguishing factor. And adds a new field comments
to MarkdownRemak type containing comments that is added with the page slug
To post a new comment, a POST /comments can be made using a form with the following field in the body of the request.
To consume a comment update any MarkdownRemark query to look like
query {
markdownRemark {
comments: {
_id
name
content
website
slug
}
}
}
And you can use the graphql helper to fetch the comments.
This comments
is an array and could be traversed and rendered using React.
<ul>
{comments &&
comments.map((comment) => {
return (
<li>
<div>{comment.author}</div>
<div>{comment.content}</div>
</li>
);
})}
</ul>
FAQs
Provides comment source for gatsby blogs
The npm package gatsby-source-comment-server receives a total of 3 weekly downloads. As such, gatsby-source-comment-server popularity was classified as not popular.
We found that gatsby-source-comment-server demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.